
Cheqpay Payment Gateway Security & Risk Analysis
wordpress.org/plugins/cheqpay-payment-gatewayAccept payments via Cheqpay with secure hosted payment page or PCI-compliant card fields on checkout.
Is Cheqpay Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100Cheqpay Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cheqpay-payment-gateway" plugin v2.2.22 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a high percentage (85%) of outputs are properly escaped, reducing the risk of cross-site scripting vulnerabilities. Furthermore, there is no recorded vulnerability history, suggesting a history of stable and secure development.
However, significant concerns arise from the static analysis. The plugin exposes a substantial attack surface through four AJAX handlers, all of which lack authentication checks. This is a critical oversight, as it allows any user, authenticated or not, to interact with these endpoints, potentially leading to unauthorized actions or information disclosure. While taint analysis did not reveal critical or high-severity issues, the presence of four flows with unsanitized paths is still a concern and could be exploited if combined with the unprotected AJAX endpoints. The absence of capability checks further exacerbates the risk associated with the unprotected AJAX handlers.
In conclusion, while the plugin benefits from secure database interactions and good output sanitization, the lack of authentication on all AJAX endpoints is a major weakness that significantly elevates the security risk. The absence of a vulnerability history is a positive indicator, but it does not negate the immediate threats posed by the unprotected attack surface. Addressing the unauthenticated AJAX handlers should be the highest priority.
Key Concerns
- 4 AJAX handlers without authentication checks
- 4 flows with unsanitized paths
- 0 capability checks present
Cheqpay Payment Gateway Security Vulnerabilities
Cheqpay Payment Gateway Code Analysis
Output Escaping
Data Flow Analysis
Cheqpay Payment Gateway Attack Surface
AJAX Handlers 4
WordPress Hooks 15
Maintenance & Trust
Cheqpay Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Cheqpay Payment Gateway Alternatives
Svea Stand Alone for WooCommerce
svea-webpay-for-woocommerce
The Svea Stand Alone payment module is a complete solution for shops using WordPress / WooCommerce as an e-commerce platform.
ATOL ECOM Payment Plugin for WooCommerce
atol-pay-gateway
Activate ATOL checkout on your WooCommerce store.
Whalet Payment
whalet-payment
Secure and convenient online payment gateway for WordPress with WooCommerce integration and flexible payment solutions.
iyzico for WooCommerce
iyzico-woocommerce
iyzico latest payment processing solution. Accept credit/debit cards, alternative digital wallets and bank accounts.
Custom Payment Gateways for WooCommerce
custom-payment-gateways-woocommerce
Custom payment gateways for WooCommerce - create custom payment gateways to never miss out any payments for your WooCommerce Store.
Cheqpay Payment Gateway Developer Profile
1 plugin · 10 total installs
How We Detect Cheqpay Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cheqpay-payment-gateway/assets/css/cheqpay-checkout.css/wp-content/plugins/cheqpay-payment-gateway/assets/js/cheqpay-checkout.js/wp-content/plugins/cheqpay-payment-gateway/assets/js/cheqpay-admin.js/wp-content/plugins/cheqpay-payment-gateway/assets/js/cheqpay-checkout.js/wp-content/plugins/cheqpay-payment-gateway/assets/js/cheqpay-admin.js/wp-content/plugins/cheqpay-payment-gateway/assets/css/cheqpay-checkout.css?ver=/wp-content/plugins/cheqpay-payment-gateway/assets/js/cheqpay-checkout.js?ver=/wp-content/plugins/cheqpay-payment-gateway/assets/js/cheqpay-admin.js?ver=HTML / DOM Fingerprints
cheqpay-payment-formdata-cheqpay-checkout-paramscheqpay_checkout_params/wp-json/cheqpay/v1/authentication_request/wp-json/cheqpay/v1/validate_authentication